{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wn572/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18607"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WN572","WN570H","WN573","WN529","WN530","WN531","WN535","WN536","WN551","WN557","NU516"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Wavlink"],"content_html":"\u003cp\u003eA critical security vulnerability, tracked as CVE-2026-18607, affects numerous Wavlink networking devices including the WN572, WN570H, WN573, WN529, WN530, WN531, WN535, WN536, WN551, WN557, and NU516 series. The vulnerability is located within the 'upload.cgi' script utilized by the embedded lighttpd web server. An unauthenticated remote attacker can trigger a stack-based buffer overflow by sending a specially crafted 'HTTP_COOKIE' header to the device. The issue stems from the unsafe implementation of the 'strcpy' function when processing this cookie input. Publicly available proof-of-concept exploits exist, increasing the risk of exploitation by threat actors targeting embedded devices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify vulnerable Wavlink devices exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request targeting the /upload.cgi endpoint on the target device.\u003c/li\u003e\n\u003cli\u003eAttacker embeds an oversized string within the 'HTTP_COOKIE' header of the malicious request.\u003c/li\u003e\n\u003cli\u003eThe lighttpd component receives the request and invokes the vulnerable 'upload.cgi' script.\u003c/li\u003e\n\u003cli\u003eThe 'strcpy' function copies the excessive cookie data into an undersized stack buffer.\u003c/li\u003e\n\u003cli\u003eThe stack-based buffer overflow results in memory corruption, overwriting return addresses.\u003c/li\u003e\n\u003cli\u003eThe attacker redirects control flow to injected shellcode or payload.\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE) is achieved on the affected device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18607 allows an attacker to achieve remote code execution on affected Wavlink networking devices. This compromises the integrity and availability of the network appliance. Given the nature of these devices, such a compromise could facilitate man-in-the-middle attacks, credential harvesting, or lateral movement into the protected internal network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify and inventory all Wavlink networking devices within the enterprise network to determine if any of the affected models are in use.\u003c/li\u003e\n\u003cli\u003eRestrict access to the web management interface of these devices by limiting access to trusted IP ranges via firewall rules.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring of HTTP requests targeting '/upload.cgi' endpoints, particularly looking for anomalous or oversized 'Cookie' headers.\u003c/li\u003e\n\u003cli\u003eEngage with the vendor to obtain firmware updates that resolve the unsafe use of 'strcpy' in 'upload.cgi'.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately available and the device is exposed to the internet, disable the web-based management interface or isolate the device from external network access.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-03T18:06:09Z","date_published":"2026-08-03T18:06:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wavlink-buffer-overflow/","summary":"Multiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.","title":"Remote Stack-Based Buffer Overflow in Wavlink Networking Devices","url":"https://feed.craftedsignal.io/briefs/2026-08-wavlink-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - WN572","version":"https://jsonfeed.org/version/1.1"}